Project

General

Profile

Documentation #42165

Feature #47765: mgr/dashboard: security improvements

mgr/dashboard: Document new password requirements in the installation documentation

Added by Lenz Grimmer about 3 years ago. Updated 8 months ago.

Status:
New
Priority:
Low
Assignee:
-
Category:
Docs
Target version:
% Done:

0%

Tags:
Backport:
Reviewed:
Affected Versions:
Pull request ID:

Description

Starting with Ceph Octopus, the Dashboard supports enforcing some minimum password complexity rules. These limitations should be documented, so users are aware when creating new user accounts. In particular, it should be noted that a password:

  • Must contain at least 8 characters
  • Cannot contain username
  • Cannot contain any keyword used in Ceph, e.g. "osd", "host", "dashboard", "pool", "block", "nfs", "ceph", "monitors", "gateway", "logs", "crush", "maps"
  • Cannot contain any repetitive characters e.g. "aaa"
  • Cannot contain any sequencial characters e.g. "abc"
  • Must consist of characters from the following groups:
    • alphabetic a-z, A-Z
    • numbers 0-9
    • special chars: !"#$%& \'()*+,-./:;<=>?@[]^_`|~
    • any other characters (signs)

Related issues

Related to Dashboard - Feature #25232: mgr/dashboard: Support minimum password complexity rules Closed

History

#1 Updated by Lenz Grimmer about 3 years ago

  • Related to Feature #25232: mgr/dashboard: Support minimum password complexity rules added

#2 Updated by Lenz Grimmer about 3 years ago

  • Description updated (diff)

#3 Updated by Ernesto Puerta about 2 years ago

  • Parent task set to #47765

#4 Updated by Lenz Grimmer about 2 years ago

  • Tags changed from security, documentation, installation to security, documentation, installation, low-hanging-fruit
  • Category changed from 150 to 175
  • Priority changed from Normal to Low

#5 Updated by Lenz Grimmer about 2 years ago

This is partially documented already here: https://docs.ceph.com/en/latest/mgr/dashboard/#password-policy

#6 Updated by Ernesto Puerta over 1 year ago

  • Project changed from mgr to Dashboard
  • Category changed from 175 to Docs

#7 Updated by Laura Flores 8 months ago

Himadri Maheshwari will work on this issue.

Also available in: Atom PDF